Prerequisites to configure Entra ID conditional access

Prerequisite

Description

Microsoft account

Verify that you have a Microsoft account with an Intune license and with one of the following Entra ID roles (or a custom role with equivalent permissions):
  • Global Administrator
  • Intune Service Administrator

Requirements for device users

  • Users must exist in Entra ID and must have a valid Intune license. For more information, see Microsoft Intune licenses.
  • If you synchronize your on-premises Active Directory with Entra ID, users’ on-premises Active Directory UPN must match their Entra ID UPN.
  • Users must be added to UEM as directory users. UEM can connect to Entra ID or Microsoft AD for the directory connection. Use Entra ID if your organization's users are cloud-only. Use AD if users are hybrid (on-premises AD synchronized to Entra ID). In either scenario UPN alignment beween UEM and Entra ID is critical for compliance evaluation.

Microsoft Endpoint Manager configuration

In the Microsoft Endpoint Manager admin center, in the section for Partner Compliance Management, add BlackBerry UEM Conditional Access as a compliance partner for iOS and Android devices and assign the compliance partner configuration to users and groups. For more information, see Microsoft Intune: Support third-party device compliance partners in Intune.

Entra ID configuration

In Entra ID, create and configure a conditional access policy and enable the option "Require device to be marked as compliant". Note that this is the only conditional access profile setting that UEM interacts with. The conditional access policy is required if you want to enforce access control based on compliance status. Without the conditional access policy, compliance is tracked but not enforced.

After you verify the prerequisites above, follow the steps in Configure Entra ID conditional access.
  • Note that the configuration steps will instruct you to enable the UEM Client to enroll in BlackBerry Dynamics and to install the UEM Client on devices.
  • The steps will instruct you to install the Microsoft Authenticator app on users' devices before activation with UEM. If you want to delay conditional access enrollment on the device until the Microsoft Authenticator app is installed (either manually by the user or deployed with UEM), you can enable the "Start Entra Conditional Access enrollment after authentication broker is installed" setting in the assigned BlackBerry Dynamics profile. Note that this option is not supported for Android devices with the User privacy activation type (it does apply to Android Enterprise user privacy and Android Management user privacy). If enabled, after the Microsoft Authenticator app is installed, the conditional access enrollment process is initiated when the user opens the UEM Client. On Android devices, if the work space is unlocked, the user will be prompted to open the UEM Client to start the conditional access enrollment.